The complete system — what wikiTaTa is and does, whole-platform view
The thesis
wikiTaTa is a bring-your-own-agent platform. You bring your own AI model and keys. The platform gives your agent what no chat product does: durable, structured, owned memory plus real operational authority, under governance you control. You own your data, projects and accumulated context, instead of renting a black box that forgets you between sessions.
It fuses three layers that are usually separate products:
- A personal wiki and knowledge canvas — a zoomable canvas where everything is a card.
- A persistent memory and governance substrate — sessions, canon discipline, directive rules, audit.
- A multi-agent operations mesh — the agent doesn't just chat: it deploys, coordinates with other agents and pages you, and is audited doing it.
Everything is a card
Notes, tasks, specs, references and decisions are all cards on a zoomable canvas: wiki-style links, project clusters, saved positions, history on every edit, never hard-deleted, pop-out windows and revocable public sharing. Tiered summaries let an agent load exactly as much as a task needs. Search works by keyword and by meaning.
Interactive decision notes stand out. The agent builds a card of questions, and the person answers inline on the card. The agent reads the answers back and resumes, with no polling and no chat round-trips.
Durable memory and session continuity
- Every session starts the same way: one call returns identity, the card index, safety rules, messages, health, and a hand-off written by the previous session.
- Every session ends by writing topic cards plus a directive for the next session.
- One canonical card per topic. New work converges onto it instead of sprawling, and a near-duplicate gate enforces that.
- Inventory first. The agent must check the registry of live capabilities before proposing to build anything.
Multi-tenant by design
Identity, content and platform are separate. Each tenant's content sits behind deny-by-default row-level security. Every request is routed by who issued its token, so a misroute is denied rather than leaked. The app has no all-powerful database key; every read and write is scoped to the user.
Secrets
Plaintext secrets exist in exactly two places: the encrypted vault and the memory of the process that uses them. Users paste secrets into a browser pop-out that encrypts them client-side, and the agent uses secrets without ever seeing them.
Agent-neutral
A hosted MCP endpoint lets any MCP-capable agent (Claude, ChatGPT, Gemini) join, with per-request authentication. Live state and rules are injected server-side on every turn, so enforcement never depends on local configuration.